Open Framework v1.1 — GA

Find cloud misconfigurations in your Terraform before you deploy.

WAFPass scans your Infrastructure-as-Code in one command. No AWS account, no setup, no cloud credentials — just a clear list of what to fix before it reaches production.

Apache 2.0 · CC BY 4.0 83+ Controls Multi-cloud
cloud.waf2p/executive
WAF++ Executive Dashboard — compliance overview for leadership WAF++ Executive Dashboard — compliance overview for leadership
GDPR · NIS2 ready
83+ controls
Audit-ready reports
Agentic-ready
No cloud credentials needed Static analysis on IaC Auditor-ready PDFs
First result in 2 minutes

Three steps to your first scan.

01
Install the CLI

One PyPI package gives you the static-analysis engine.

pip install wafpass-core
02
Run one command

Point WAFPass at your Terraform folder and get a JSON summary.

wafpass check . --output json | jq '.summary'
03
See what's wrong

A clear pass/fail count and per-control findings tell you exactly what to fix.

81 passed · 2 failed

What a first finding looks like

WAFPass flags a public S3 bucket and shows the exact control and the fix.

FAIL SEC-S3-001

S3 bucket public access block is disabled. Public buckets expose data to the internet.

Fix snippet
resource "aws_s3_bucket_public_access_block" "public" {
  bucket                  = aws_s3_bucket.public.id
  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}
8
Pillars
83+
Controls
50+
Compliance frameworks
0%
Vendor lock-in
1M+
IaC resources assessable
100%
Open source & transparent
REFERENCES

Trusted by cloud practitioners.

WAF++ provides a stable foundation for digital applications and shows how technical precision and design sensitivity can be successfully combined.
Lydia Hundsdörfer
Lydia Hundsdörfer
Project & Partner Manager, Vogel IT
WAF++ has great potential to become the perfect answer to real-world everyday questions from the technology, cloud & developer community.
Maximilian Hille
Maximilian Hille
Cloud Analyst
For the first time we can show our board a single, vendor-neutral score for cloud workload quality instead of slide decks full of gut feeling.
Dr. Elena Voss
Dr. Elena Voss
CISO, Finova Group
WAFPass caught misconfigurations in Terraform before they reached production. That alone saved us a full audit cycle.
Marcus Chen
Marcus Chen
VP of Engineering, ScaleFlow
The sovereign pillar gives us a clear language for residency and control discussions with regulators and customers.
Sarah Bennett
Sarah Bennett
Cloud Architect, Nordisys AG
Mapped to leading compliance frameworks
GDPR SOC 2 HIPAA BSI C5 ISO 27001 NIS2 PCI DSS DORA ISO 27017 NIST 800-53
Why ++

Two extra pillars for a world that classic frameworks weren't built for.

WAF++ takes the six proven Well-Architected pillars and adds the two that matter most for modern, regulated, AI-assisted cloud operations.

+01

Sovereign

Digital sovereignty, data residency, and vendor independence. The first plus keeps your architecture under your control.

+02

Agentic

Policy-aware autonomous agents and AI-assisted architecture reviews. The second plus makes the framework ready for the agentic era.

WAFPass

Compliance checks that run before the cloud.

The open-source WAFPass platform scans Terraform, AWS CDK, and more — no credentials, no API calls, just fast, traceable results.

cloud.waf2p/runs
WAFPass Run Dashboard WAFPass Run Dashboard
Static analysis on .tf files
8 pillars covered
PDF reports for auditors
CI/CD ready native hooks
Quick start
git clone https://github.com/WAF2p/wafpass-core.git

For the full Docker Compose stack (CLI + Server + Dashboard) see the complete installation guide.

How it works

From code to compliance in three steps.

01
Write Terraform

Build infrastructure-as-code the way you already do. WAF++ stays out of your workflow.

02
Run WAFPass

Static analysis checks every resource against WAF++ controls — no cloud credentials needed.

03
Ship compliant

Export PDF reports, block violations in CI, and prove governance to auditors.

Get started

Ready to build cloud architecture with intention?

Join the community, read the docs, or run your first WAFPass scan today.

GDPR SOC 2 HIPAA BSI C5 ISO 27001 NIS2